https://seclists.org/oss-sec/2026/q2/105: GNU tar: listing/extraction desynchronization allows hidden file injection
Published Apr 11, 2026
·Updated
Affected Software
1 affected component
GNU GNU tar
Frequently Asked Questions
1
What is the severity of CVE-2026-5704?
CVE-2026-5704 is considered a high-severity vulnerability due to the potential for hidden file injection during archive extraction.
2
How do I fix CVE-2026-5704?
You can fix CVE-2026-5704 by applying the patch provided by Paul Eggert, which is available in the relevant bug report.
3
What software is affected by CVE-2026-5704?
The CVE-2026-5704 vulnerability affects GNU tar, a widely used archiving tool.
4
What are the potential impacts of CVE-2026-5704?
The potential impacts of CVE-2026-5704 include unauthorized file access and the ability for attackers to inject arbitrary hidden files into the filesystem.
5
When was CVE-2026-5704 published?
CVE-2026-5704 was published on April 11, 2026.